Privacy Policy
1. Introduction
Vavo Chat ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our messaging application and related services.
Our fundamental design principle is privacy first. We employ end-to-end encryption using the Signal Protocol, maintain a zero-knowledge server architecture, and minimize data collection to only what is essential for the Service to function. Where we do hold data, this policy says so plainly and explains why.
2. Information We Collect
2.1 Account Information
- Email address (if you register with email) or phone number (if you register with phone/OTP)
- Hashed password (for email-based accounts only)
- Your unique 8-digit hexadecimal PIN code (generated at registration)
- Device information for session management
- A device installation identifier. When you sign in, your app supplies a best-effort identifier for the installation. We use it for one purpose: so that an account ban cannot be evaded by immediately registering a fresh account on the same device. Without it, a banned user is back within seconds and the people they were harassing get no relief. It is not an advertising identifier, it is not used to profile you or track you between apps or websites, and it is never shared with anyone.
- If you sign in with Apple or Google: the provider name, the subject identifier they issue for you, the email address they return (which may be an Apple private relay address), and the display name and avatar they supply. We also retain the provider's refresh token, solely so that deleting your account can revoke the connection at the provider as Apple requires.
- If you register a passkey: the public credential and its metadata. The private key never leaves your device.
- If you enable two-factor authentication: your TOTP secret and hashed single-use recovery codes.
2.2 Your Contacts and Connections
Your contact list is held on our servers, not only on your device. We want to be direct about this because it is the kind of thing a privacy policy should not bury:
- What we store: which accounts you have added as contacts, any nickname or favourite marking you give them, when the contact was added, and any pending contact requests together with the optional message attached to them.
- Why: a contact request has to reach someone who is offline and wait for them to accept or decline, and your contact list has to look the same on your phone and in the web companion. Neither is possible if the relationship exists only on one device.
- What we do not store: your device's address book. Vavo Chat never uploads your phone contacts. Connections are made by 8-digit PIN, so we never learn the phone numbers or email addresses of people you talk to unless they are Vavo Chat users themselves.
We similarly store group membership and per-conversation settings, because a group has to exist for every member independently of any one device.
2.3 Information We Do NOT Collect
- Message content - all messages are end-to-end encrypted and we cannot read them
- Media files in plaintext - all media is encrypted client-side before upload
- Your device's address book or phone contacts - never uploaded
- Location data - Vavo Chat does not request or access your device location
- Browsing history or app usage analytics
2.4 Messages and How Long They Are Kept
- Encrypted message payloads. A message is held on the server only until every one of the recipient's devices confirms receipt, at which point it is deleted. If a recipient never comes back online, their encrypted messages stay queued until they do, or until the account is deleted. We cannot read any of it at any point.
- Delivery receipts. When a message is delivered we keep a small durable record - sender, recipient, message identifier and timestamp - so that the sender's delivery ticks still arrive if the sender was offline at that moment. These records contain no message content and are automatically swept after a short period.
- Encrypted media. Media blobs are stored encrypted, expire automatically, and are removed by a scheduled cleanup.
- Signal Protocol pre-key bundles, so other people can start an encrypted session with you.
2.5 Network and Security Logs
We record IP addresses. They reach us when your app or browser connects to our servers, when a sign-in or registration is attempted, and through our reverse proxy's access log. We use them to rate-limit requests, to detect and stop brute-force and abuse attempts, and to diagnose outages. This is a security measure and nothing else: IP addresses are never used for advertising, profiling or tracking, and are never sold or shared for marketing.
Security logs containing IP addresses are retained for 30 days and then deleted.
2.6 Push Notification Tokens
We store the push token your device's operating system issues, so that notifications can be delivered to it.
3. How We Use Your Information
- To create and manage your account
- To facilitate encrypted message, story and call delivery
- To enable device-based session management
- To send push notifications for incoming messages and calls
- To keep the Service secure, rate-limit abuse and prevent ban evasion
- To process content moderation reports (submitted voluntarily by recipients)
- To provide customer support
4. End-to-End Encryption
All messages sent through Vavo Chat are encrypted using the Signal Protocol (X3DH key agreement + Double Ratchet algorithm). This means:
- Messages are encrypted on your device before transmission
- Only the intended recipient(s) can decrypt and read messages
- Our servers only relay encrypted blobs - we have zero access to plaintext
- Group messages use Sender Keys encryption for efficient group communication
- Media files are encrypted with AES-256-GCM before upload
- Stories and call setup messages are encrypted the same way (see sections 5 and 6)
Push notifications carry the encrypted message so your device can decrypt and display it without waking the app. The payload is ciphertext: Apple, Google and we ourselves cannot read it.
5. Voice and Video Calls
- Call setup (the offer, answer and connection candidates) is end-to-end encrypted with the Signal Protocol and relayed through our servers without being stored. No call log, call history or call duration record is kept on our servers.
- Call media uses WebRTC and is encrypted in transit. Where the two devices can reach each other directly, the audio and video never touch our infrastructure at all.
- When a direct connection is not possible - typically behind restrictive networks - media is relayed through our own TURN server. The relay forwards encrypted media and cannot decrypt it, but it necessarily sees the IP addresses of both participants for the duration of the call.
- Incoming call alerts are delivered through Apple's and Google's push services. Those alerts tell the provider that a call is arriving for your device and whether it is audio or video. They carry no call content.
- On iOS, calls are presented through the system call interface, which means iOS records them in your device's own call history. That record belongs to your device and is outside our control; if you have iCloud syncing enabled, Apple may sync it.
6. Stories
- Story media is encrypted on your device before upload and stored encrypted. The decryption key and any caption travel inside a separate Signal-encrypted envelope addressed to each viewer, so the server holds the media and the key-bearing envelopes but can open neither.
- Stories expire 24 hours after posting and are deleted automatically.
- We deliberately keep no record of who viewed your story. View receipts are relayed to you end-to-end encrypted; the server never learns who watched what.
7. Content Moderation and Reports
Because messages are end-to-end encrypted, we cannot see their content and cannot proactively scan, filter or monitor anything you send. That is a deliberate trade-off, and it has a consequence worth stating openly: the only way we can act against harassment or illegal content is if someone who received it chooses to show it to us.
- What happens when you report a message. Your app decrypts the message on your device and uploads the readable content to us. For media, your app uploads a decrypted copy into a separate, access-controlled moderation store. This is the only circumstance in which readable message content or media ever reaches our servers, and it happens only because a participant in the conversation chose to send it. We never decrypt anything ourselves.
- What the report contains. The reported content, the account identifiers of the sender and the reporter, the message's timestamp, the reason selected and any free-text explanation, and later the review outcome and any warning issued.
- Who can see it. Reports are visible only to moderation staff through an access-controlled admin interface, and every administrative action taken on a report is written to an audit log.
- Bear in mind that reporting necessarily discloses the reported message to us. If you report a message, you are choosing to break the end-to-end guarantee for that specific message.
- Retention. Reported media is deleted automatically when its retention period expires. Reported text is kept while the report is open and for up to 12 months after it is resolved, so that repeat behaviour can be recognised, and is then deleted.
8. Account Restrictions and Moderation Records
To enforce our Terms and protect other users, we keep a record when an account is warned or restricted. We disclose this in full because it is data about you that we hold and that you cannot see all of:
- Whether an account is banned, when, and the reason - the reason is shown to you the next time you try to sign in.
- Warnings issued to an account, and whether you acknowledged them.
- Notes recorded by moderation staff while reviewing a case, and an audit log of the administrative actions taken.
- Device-level bans, recorded against the device installation identifier described in section 2.1. The justification is the same: a ban that can be shrugged off by creating a new account in the same minute protects nobody.
You can review the security events affecting your own account - new device sign-ins, passkey registrations, password changes and similar - in the app's privacy dashboard.
9. Data Storage
Vavo Chat operates on a zero-knowledge server architecture:
- Server-side: encrypted message payloads awaiting delivery, encrypted media, account and connection metadata as described in section 2. Message content is never stored in plaintext, with the single exception of content you yourself report to us (section 7).
- Device-side: your full message history and preferences are stored locally on your device and protected by OS-level encryption.
- On-premises: the entire infrastructure is self-hosted with no cloud provider dependency.
10. Third-Party Services
We use the following third-party services in a limited capacity:
- SMS Providers (Twilio/Sent.dm): for OTP verification during phone-based registration only
- Push Notification Services (APNs/FCM): for delivering message and call notifications. Payloads contain only end-to-end encrypted content, which the provider cannot read.
- Email Services (Mailgun): for transactional emails (account verification, security alerts)
- Sign in with Apple and Sign in with Google: used only if you choose them. The provider learns that you signed in to Vavo Chat; we receive the identifiers described in section 2.1. The Google sign-in library is embedded in our mobile app and is only exercised if you use that option.
- Passkeys: handled by your device and operating system. We store only the public credential.
Everything else - the API, database, media storage, TURN relay, and this website - runs on our own infrastructure.
11. Cookies and Local Storage
This website stores your light/dark theme preference in your browser's local storage. We do not use tracking cookies, advertising cookies, or analytics cookies.
12. Your Rights
You have the right to:
- Access: view your account information through the app
- Data Export: a self-service export of your data is a planned feature and is not available yet. Until it ships, contact us and we will provide the data we hold about you.
- Deletion: delete your account from within the app. Doing so erases your email address, phone number, password, avatar and status message, deletes your undelivered messages and your contacts, revokes every signed-in device, unlinks and revokes any Apple or Google connection, and anonymises your profile. One thing deliberately survives: your 8-digit PIN stays reserved so that it can never be reissued to somebody else, who would otherwise inherit your old QR codes and invitation links and start receiving messages meant for you. The reserved PIN is not linked to any personal data. Because your message history lives on your device, the server never held it in the first place.
- Correction: update your account information at any time
- Revocation: revoke device sessions and manage active connections
13. Children's Privacy
Vavo Chat is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it.
14. Data Security
We employ multiple layers of security:
- TLS 1.3 for all client-server communication
- Signal Protocol for message-level encryption
- AES-256-GCM for media file encryption
- OS-level encryption for on-device data storage
- Rate limiting, account lockout after repeated failed sign-ins, and optional two-factor authentication
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or email. The "Last updated" date at the top of this page indicates when the policy was last revised.
16. Contact Us
For privacy-related inquiries, please contact us at [email protected] or visit our Support page.